Docker layers can be fast for developers but also vulnerable if not audited for production. Wouldn’t it be great to improve continuous integration with continuous vulnerability detection?
Clair, an open source tool to monitor the security of containers, is an API-driven analysis engine that inspects containers layer by layer for known security flaws. Quentin Machu offers an overview of Clair and explores a real-life example to demonstrate how Clair is able to automatically detect known vulnerabilities in Docker and rkt containers before they get exploited, using graph database queries to track package changes.
Join Quentin to get started using Clair and learn to easily build services that provide continuous monitoring for container vulnerabilities.
Quentin Machu is an engineer on the Quay team at CoreOS and a maintainer of the Clair open source project, which scans containers for vulnerabilities. He is passionate about software engineering and distributed systems. Quentin completed an award-winning OpenStack project as part of his master’s in computer engineering.
©2016, O’Reilly UK Ltd • (800) 889-8969 or (707) 827-7019 • Monday-Friday 7:30am-5pm PT • All trademarks and registered trademarks appearing on oreilly.com are the property of their respective owners. • email@example.com